Explain the mirrorOf matching syntax, including external:* and negation. How do you mirror everything except one internal repo?
answer
- matched against repo id
- *, external:*, external:http:*
- comma list of ids
- negation !id with *
- first match wins
basics
~10 smirrorOf decides which repository ids a mirror handles. Use * for all, external:* for non-local ones, a comma list of ids, or *,!internal to mirror everything except the repo with id 'internal'.
solid answer
~40 s`<mirrorOf>` is a pattern matched against each declared repository's `<id>`. Supported forms: a single id (`central`); `*` (all repos); `external:*` (all except `localhost` and `file://` repos); `external:http:*` (external plain-HTTP only); a comma-separated id list (`repo1,repo2`); and negation with `!` (`*,!internal`). To mirror everything except an internal repo you write `<mirrorOf>*,!internal</mirrorOf>`, which keeps the `internal` repository resolving directly to its own URL while routing all others through the mirror. `external:*` is the practical default for corporate setups because it leaves local file repositories and integration-test localhost repos untouched. Only the first matching mirror is applied, so when multiple mirrors exist, ordering and specificity matter.
code
xml · 5 lines<mirror>
<id>corp-nexus</id>
<url>https://nexus.corp.example/repository/maven-public/</url>
<mirrorOf>*,!internal-snapshots</mirrorOf>
</mirror>go deeper
Knows * means all repositories.
Can write external:* and *,!id patterns and explain what each excludes.
Orders mirrors for first-match correctness and avoids breaking localhost/file test repos.
Standardizes a mirrorOf convention across the org and audits for overlapping/shadowing mirrors.
## The mirrorOf grammar Maven evaluates `<mirrorOf>` against the **id** of each repository it is about to contact. The accepted tokens: - **`<id>`** — exact id match, e.g. `central` mirrors only the Central repository. - **`*`** — wildcard, matches every repository. - **`external:*`** — matches every repository **whose URL is not** `file://` and **whose host is not** `localhost`/`127.0.0.1`. Useful so that locally served test repos still resolve directly. - **`external:http:*`** — same as above but restricted to plain-`http` URLs (not `https`); rarely needed. - **comma list** — `repo1,repo2,central` matches any of those ids. - **negation `!id`** — excludes an id. Combine with `*`: `*,!internal` = everything except `internal`. ## Combining patterns Patterns are comma-separated and evaluated left to right; a later negation can subtract from an earlier wildcard. Common recipes: - `*` — funnel literally everything through the manager (also mirrors plugin repos and local test repos). - `external:*` — funnel external repos only; safest general corporate setting. - `*,!snapshots` — mirror everything but let a repo id `snapshots` resolve directly. ## First-match wins If several `<mirror>` entries could match, Maven uses the **first** one in document order that matches. So put more specific mirrors before broad ones. Two mirrors with overlapping `mirrorOf` is a frequent misconfiguration. ## Example: mirror all but one internal repo ```xml <mirrors> <mirror> <id>corp-nexus</id> <url>https://nexus.corp.example/repository/maven-public/</url> <mirrorOf>*,!internal-snapshots</mirrorOf> </mirror> </mirrors> ``` Here a repository declared in the pom with `<id>internal-snapshots</id>` keeps using its own URL, while Central, plugin repos, and any third-party repos go through Nexus. ## Why external:* matters Integration tests sometimes spin up a `file://` or `http://localhost` repository. With `*` those would be (wrongly) redirected to the corporate manager and break. `external:*` leaves them alone.
- What does external:* exclude that * does not?Repositories on localhost/127.0.0.1 and those using file:// URLs are left to resolve directly.
- If two mirrors both match a repo, which one is used?The first matching mirror in settings.xml document order; remaining matches are ignored.
saying these in an interview costs you the question
- Claiming mirrorOf matches repository URLs (it matches ids)
- Thinking negation works alone without a wildcard
- Believing all matching mirrors are merged rather than first-match-wins